Skip to content

v0.7.0

Choose a tag to compare

@cjohannsen81 cjohannsen81 released this 06 Sep 16:42
· 29 commits to main since this release

Per-user on-behalf-of credentials

The roadmap's loudest ask. By default the proxy holds one credential per upstream and everyone shares it; now you can mark an upstream per_user: true and each caller reaches it with their own credential, so the upstream sees the actual person and their individual permissions, not a shared robot account. The caller's own token is still never forwarded upstream.

The per-user credential is resolved per request through a pluggable hook you control:

  • obo.command — your vault or token-exchange script, run with AGGRETE_USER and AGGRETE_UPSTREAM in the environment, printing {"env": {...}, "headers": {...}}.
  • obo.users — a static per-user map.
  • default — with no obo, the caller's identity is passed as AGGRETE_ACTING_USER so a delegation-aware connector can act as them.

The resolved env is merged into a stdio connector's environment; headers into an HTTP upstream's request headers (the per-user value wins). A per-user upstream opens a fresh connection per call for isolation; shared upstreams keep the single long-lived session. Every decision records who the call acted as. See the "Per-user access (on-behalf-of)" section in the README.

No change to existing shared-credential upstreams. Connection pooling for per-user sessions is the next optimization.